Medium · 5.3 Node.js & npm GHSA-v3xr-g6p2-fvgv CVE-2026-104414 GHSA-jj74-hc2q-xrvm CVE-2026-104418
Ghost CMS: Eight Vulnerabilities Patched, Including Stored XSS and Admin RCE
Eight vulnerabilities in Ghost CMS have been disclosed and fixed, ranging from stored cross-site scripting and admin-triggered remote code execution to path traversal and information disclosure issues. Most affected installations are fixed in version 6.64.0; one issue was fixed earlier in 6.27.0 and another in 6.44.1.
- OSV.dev database 1d ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- OSV.dev database 1d ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- OSV.dev database 1d ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- OSV.dev database 1d ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- OSV.dev database 1d ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- OSV.dev database 1d ago · view ↗
- NVD (NIST) database 4d ago · view ↗
- OSV.dev database 1d ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- OSV.dev database 1d ago · view ↗
- NVD (NIST) database 1w ago · view ↗
AI summary
Ghost, the open-source publishing platform, has disclosed and patched eight separate vulnerabilities affecting a wide range of versions. The issues include two stored cross-site scripting (XSS) vulnerabilities, a remote code execution (RCE) flaw exploitable by administrators, two path traversal vulnerabilities, and three information disclosure weaknesses in the Admin API and comments feature. Most of these issues were fixed in Ghost 6.64.0; two were fixed in earlier releases (6.27.0 and 6.44.1). None of the vulnerabilities are reported as actively exploited or have public exploit code available.
Overview of the Vulnerabilities
Eight CVEs were published for Ghost CMS, covering a broad range of weaknesses. CVE-2026-104414 and CVE-2026-104413 are stored XSS vulnerabilities that allow injection of scripts via oEmbed photo responses and bookmark card image fetching, respectively. CVE-2026-104418 allows an authenticated administrator to achieve remote code execution by uploading a theme with malicious translation files. CVE-2026-104417 is a related path traversal issue in theme translation file loading that lets administrators read JSON files outside the active theme directory. CVE-2026-103290 is a path traversal issue in the ImageSize service. CVE-2026-104415 and CVE-2026-104416 are information disclosure issues in the Admin API, involving password hash ordering and invite token exposure, respectively. CVE-2026-103289 is an authorization bypass in the comments feature, allowing members to view comments they should not have access to.
Root Causes
The stored XSS vulnerabilities (CVE-2026-104414, CVE-2026-104413) stem from insufficient validation of externally hosted content embedded into posts: oEmbed photo responses and bookmark card thumbnails can be crafted to store and execute scripts in the Ghost editor, published site, or newsletter emails. The RCE vulnerability (CVE-2026-104418) and the related path traversal flaw (CVE-2026-104417) both arise from how Ghost loads theme translation files, allowing crafted files or manipulated locale settings to execute code or read arbitrary JSON files on the server. CVE-2026-103290 is caused by insufficient validation of user-supplied file paths in the ImageSize service. The two information disclosure issues (CVE-2026-104415, CVE-2026-104416) result from the Admin API exposing data that should remain restricted: relative password hash ordering and secret invite tokens. CVE-2026-103289 is an input validation issue in the comments feature that fails to properly restrict access to comment data.
Why This Matters
Several of these vulnerabilities can lead to compromise of staff admin sessions (via stored XSS) or full server compromise (via the RCE flaw). The RCE vulnerability (CVE-2026-104418) is particularly serious because it allows an administrator-level attacker, or an attacker who compromises an admin account, to execute arbitrary code on the server. The two information disclosure flaws can be chained: CVE-2026-104416 specifically notes that exposure of invite tokens can allow privilege escalation, as staff users could accept pending invites for higher-privileged roles. While several issues require authenticated staff or administrator access, the combination of stored XSS, privilege escalation potential, and RCE makes timely patching important.
Who Is Affected
Any self-hosted or managed Ghost CMS instance running a version within the affected ranges is at risk. The affected version ranges vary per vulnerability: CVE-2026-104414 affects versions from 2.5.0 before 6.64.0; CVE-2026-104418 affects versions from 6.10.3 before 6.64.0; CVE-2026-103290 affects versions from 6.14.0 before 6.27.0; CVE-2026-104415 affects versions from 0.7.2 before 6.64.0; CVE-2026-104417 affects versions from 1.20.0 before 6.64.0; CVE-2026-104416 affects versions from 4.39.0 before 6.64.0; CVE-2026-104413 affects versions from 5.94.0 before 6.64.0; CVE-2026-103289 affects versions from 5.9.0 before 6.44.1.
Affected and Fixed Versions
Ghost versions 2.5.0 up to but not including 6.64.0 are affected by CVE-2026-104414 (fixed in 6.64.0). Versions 6.10.3 up to but not including 6.64.0 are affected by CVE-2026-104418 (fixed in 6.64.0). Versions 6.14.0 up to but not including 6.27.0 are affected by CVE-2026-103290 (fixed in 6.27.0). Versions 0.7.2 up to but not including 6.64.0 are affected by CVE-2026-104415 (fixed in 6.64.0). Versions 1.20.0 up to but not including 6.64.0 are affected by CVE-2026-104417 (fixed in 6.64.0). Versions 4.39.0 up to but not including 6.64.0 are affected by CVE-2026-104416 (fixed in 6.64.0). Versions 5.94.0 up to but not including 6.64.0 are affected by CVE-2026-104413 (fixed in 6.64.0). Versions 5.9.0 up to but not including 6.44.1 are affected by CVE-2026-103289 (fixed in 6.44.1).
Fixes
Fixes are available for all eight vulnerabilities. Six of the eight issues (CVE-2026-104414, CVE-2026-104418, CVE-2026-104415, CVE-2026-104417, CVE-2026-104416, CVE-2026-104413) are resolved in Ghost version 6.64.0. CVE-2026-103290 was fixed earlier in version 6.27.0, and CVE-2026-103289 was fixed in version 6.44.1. Instances running versions prior to these fixed versions remain vulnerable to the corresponding issues.
Recommended Actions
Site operators should update Ghost to version 6.64.0 to address the majority of these vulnerabilities, ensuring the deployed version is at or above this release. If running an older installation that has not yet reached 6.27.0 or 6.44.1, prioritize updating to at least 6.64.0 to cover all disclosed issues in a single update. Review staff and administrator accounts for signs of unauthorized access, and audit theme files and bookmark/embed content for suspicious injected scripts, particularly if upgrades have been delayed.
PatchBriefing score
5.3 / 10 · Medium
Official CVSS: 8.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Why this score
The individual patchwire scores for these vulnerabilities range from 1.5 to 5.3, reflecting a mix of severities. The highest-scored issue, CVE-2026-104414 (stored XSS via oEmbed, CVSS 8.6, score 5.3), requires user interaction and does not require authentication, contributing to its elevated score. CVE-2026-104418 (admin RCE, CVSS 8.6, score 4.9) requires administrator privileges, which lowers its score despite the high CVSS. None of the eight vulnerabilities are known to be actively exploited, have public exploit code, or have an associated EPSS score, which keeps contributions from those factors at zero across all items. Fixes are available for all issues, which also prevents score inflation from the 'no fix available' factor.
Affected versions
- ghost ≥ 2.5.0 < 6.64.0
- vulnerable
- ≥ 6.64.0
- patched
- ghost ≥ 6.10.3 < 6.64.0
- vulnerable
- ≥ 6.64.0
- patched
- ghost ≥ 6.14.0 < 6.27.0
- vulnerable
- ≥ 6.27.0
- patched
- ghost ≥ 0.7.2 < 6.64.0
- vulnerable
- ≥ 6.64.0
- patched
- ghost ≥ 1.20.0 < 6.64.0
- vulnerable
- ≥ 6.64.0
- patched
- ghost ≥ 4.39.0 < 6.64.0
- vulnerable
- ≥ 6.64.0
- patched
- ghost ≥ 5.94.0 < 6.64.0
- vulnerable
- ≥ 6.64.0
- patched
- ghost ≥ 5.9.0 < 6.44.1
- vulnerable
- ≥ 6.44.1
- patched
Reported fixes
Fixes are available for all eight vulnerabilities. Six of the eight issues (CVE-2026-104414, CVE-2026-104418, CVE-2026-104415, CVE-2026-104417, CVE-2026-104416, CVE-2026-104413) are resolved in Ghost version 6.64.0. CVE-2026-103290 was fixed earlier in version 6.27.0, and CVE-2026-103289 was fixed in version 6.44.1. Instances running versions prior to these fixed versions remain vulnerable to the corresponding issues.
How this was built
16 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
NVD (NIST) database
-
OSV.dev database
-
NVD (NIST) database
-
OSV.dev database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email